# 302 vs 307 Redirects

> Compare 302 Found and 307 Temporary Redirect, including method preservation, request bodies, browser behavior, caching, and safe API redirect choices.

Source: https://howhttpworks.com/compare/302-vs-307
Last reviewed: 2026-10-04

> **TL;DR:** Both are temporary redirects. A client that follows a 307 must resend the same method and body; one that follows a 302 may switch POST to GET, and browsers do. Use 307 to move an API call temporarily, 303 to send a browser to a result page after a POST, and 302 for plain GET navigation.

## The Core Difference

Both responses say that the requested resource is temporarily available at the URL in the `Location` header. The difference is what the client does with the original HTTP method and body.

When a client automatically follows a `307 Temporary Redirect`, it must repeat the request using the same method and body. A `POST` remains a `POST`, a `PUT` remains a `PUT`, and their payloads are sent to the new location.

With `302 Found`, user agents historically changed a `POST` into a `GET` when following the redirect. Modern HTTP semantics permit this behavior for compatibility, so an application cannot rely on method preservation after a 302.

| Behavior | 302 Found | 307 Temporary Redirect |
|---|---|---|
| Redirect is temporary | Yes | Yes |
| GET and HEAD remain unchanged | Yes | Yes |
| Non-GET method guaranteed to be preserved | No | Yes |
| Request body guaranteed to be preserved | No | Yes |
| Useful after a successful form POST | Sometimes, but prefer 303 | No, unless repeating POST is intended |
| Useful for temporary API relocation | Risky | Yes |

## Why Historical Behavior Matters

Consider an API receiving this request:

```http
POST /v1/orders HTTP/1.1
Host: api.example.com
Content-Type: application/json

{"sku":"A-42","quantity":1}
```

If `/v1/orders` returns a 302, a client may follow the redirect as:

```http
GET /v2/orders HTTP/1.1
Host: api.example.com
```

The method and payload have been lost. If the client automatically follows a 307 response, it must repeat the original `POST` and body at `/v2/orders`.

## When to Use 302

Use 302 for a temporary navigation where requests are GET or HEAD, or where compatibility behavior is intentional and tested. Examples include temporarily routing users to a maintenance page or selecting a temporary presentation URL.

Do not use 302 when correctness depends on preserving a non-GET method. Even if one tested client preserves the method, another conforming client may use the historical POST-to-GET behavior.

## When to Use 307

Use 307 when an endpoint is temporarily hosted elsewhere and the receiving endpoint is designed to accept the same method and body. This is especially relevant for APIs, upload endpoints, and temporary infrastructure routing.

```http
HTTP/1.1 307 Temporary Redirect
Location: https://uploads.example.net/v1/files
Cache-Control: no-store
```

Only redirect a credential-bearing request to an origin you trust. Redirecting an `Authorization` header or request body across origins can expose sensitive data, and clients may deliberately strip credentials during the redirect.

## When 303 Is the Better Choice

After successfully processing a form submission, applications often want the browser to load a result page with GET. Use [303 See Other](https://howhttpworks.com/status-codes/303) to express that behavior explicitly:

```http
HTTP/1.1 303 See Other
Location: /orders/123/confirmation
```

This avoids accidental resubmission when the user refreshes the result page. A 307 would repeat the POST and could create a duplicate operation if the endpoint is not idempotent.

## Caching and Search Indexing

Neither status is permanently cacheable merely because of its status code. Explicit cache headers can make a temporary redirect reusable for a limited period, but keep that lifetime short enough for the original URL to resume service when expected.

Because both redirects are temporary, the original URL should normally remain the canonical address. Use [301](https://howhttpworks.com/status-codes/301) or [308](https://howhttpworks.com/status-codes/308) when the move is permanent.

## Decision Rule

- Temporary GET navigation: 302 or 307; 302 is widely conventional.
- Temporary relocation that must preserve method and body: 307.
- POST completed; load a result page with GET: 303.
- Permanent move that may convert POST to GET: 301.
- Permanent move that must preserve method and body: 308.

Use the [Redirect and Canonical Auditor](https://howhttpworks.com/tools/redirect-audit) to inspect deployed redirect behavior.

## Seeing it in practice

```bash
curl -si -X POST https://api.example.com/v1/orders -H 'Content-Type: application/json' -d '{"sku":"A-42"}'
# HTTP/2 307
# location: https://api.example.com/v2/orders

# curl does not follow redirects unless -L. With -L, a 301/302 turns the POST into a GET
# (--post302 keeps POST); a 307/308 keeps the method and body.
curl -siL -X POST https://api.example.com/v1/orders -d '{"sku":"A-42"}'
```

Chrome DevTools shows `307 Internal Redirect` for a request that never touched the network: the browser applied a cached HSTS rule and upgraded `http://` to `https://`. Your server did not send it. Look for `Non-Authoritative-Reason: HSTS` in the response headers.

A common trap: fetch implementations drop the `Authorization` header when a redirect crosses to another origin, so a 307 to a different host can turn into a 401 on the second hop.

## FAQ

### Is 307 the same as 302?

Not quite. Both mean the target URL is temporary, but RFC 9110 lets clients change POST to GET on a 302 (section 15.4.3) and forbids changing the method on a 307 (section 15.4.8). Browsers do change the method on a 302 after a POST.

### Should I use 302 or 307 for a temporary redirect?

For GET and HEAD pages either works, and 302 is the convention. For POST, PUT, PATCH or DELETE endpoints use 307, so the method and body are preserved. To make a browser load a confirmation page with GET after handling a POST, use 303.

### Why does Chrome show 307 Internal Redirect?

Chrome synthesizes it when HSTS forces an `http://` request to `https://` before any request is sent. Clear the HSTS entry at `chrome://net-internals/#hsts` if you need to test the plain HTTP response.

### Do 302 and 307 hurt SEO?

They tell search engines the move is temporary, so the original URL normally stays indexed. A temporary redirect left in place for a long time may eventually be treated as permanent by Google; use 301 or 308 for real moves.

### Are 302 and 307 cached?

Not by default. They are cacheable only when the response carries explicit freshness information such as `Cache-Control: max-age=60` (RFC 9111 section 4.2.2).

## References

- [RFC 9110: 302 Found](https://www.rfc-editor.org/rfc/rfc9110#section-15.4.3)
- [RFC 9110: 307 Temporary Redirect](https://www.rfc-editor.org/rfc/rfc9110#section-15.4.8)
- [MDN: 302 Found](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/302)
- [MDN: 307 Temporary Redirect](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/307)
- [MDN: Redirections in HTTP](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Redirections)
